CVE-2026-82472
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
- Published Aug 29, 2026
- CVSS 8.7 high
- 0.8% chance of exploitation in the next 30 days (EPSS)
- A fix is available